CVE-2026-33179Disclosure(libfuse_project / libfuse)

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch libfuse_project libfuse systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause resource exhaustion. When numa_alloc_local fails during io_uring queue entry setup, the code proceeds with NULL pointers. When fuse_uring_register_queue fails, NUMA allocations are leaked and the function incorrectly returns success. Only the io_uring transport is affected; the traditional /dev/fuse path is not affected. PoC confirmed with AddressSanitizer/LeakSanitizer. This issue has been patched in version 3.18.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libfuse

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-21); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
libfuse

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-24: 2Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-24: 2Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-24: 2Technical Details · 2026-03-30: 103-2103-2403-3003-31
Signal classification3 categories
Disclosure
350.0%
PoC
233.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-03-242
PoC2
2026-03-301
Patch1
2026-03-311
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    libfuse: io_uring memory safety vulnerabilities https://www.openwall.com/lists/oss-security/2026/03/21/2 Affected versions: libfuse >= 3.18.0, < 3.18.2 Fixed in: libfuse 3.18.2 CVE-2026-33150: Use-After-Free CVE-2026-33179: NULL Pointer Dereference + Memory Leak

    Post summary

    An advisory discloses use‑after‑free and null‑pointer dereference/memory leak bugs in libfuse 3.18.0–3.18.2, specifies a patch in 3.18.2, and provides no evidence of active exploitation.

    0501171.8K
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Researchers uncover two flaws in libfuse's io_uring transport (CVE-2026-33150 & 33179). Impacting Kubernetes CSI drivers, these bugs allow RCE and DoS. Patch now! #libfuse #LinuxSecurity #CyberSecurity #Kubernetes #io_uring #CVE #InfoSec #CloudSecurity https://securityonline.info/libfuse-io-uring-vulnerabilities-cve-2026-33150-cve-2026-33179/ https://t.co/meyHCKpXto

    Post summary

    Researchers identified two RCE/DoS bugs in libfuse’s io_uring transport that impact Kubernetes CSI drivers, and a patch has already been released.

    031111562
    12.3K followersView on X
  • CSIRT Italia@csirt_it
    PoC

    ‼️ #Libfuse: disponibile #PoC per lo sfruttamento delle CVE-2026-33150 e CVE-2026-33179 Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔸 Privilege Escalation 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/libfuse-disponibile-poc-per-lo-sfruttamento-delle-cve-2026-33150-e-cve-2026-33179 🔄 Aggiornamenti disponibili 🔄 https://t.co/LmbQh1oLhD

    Post summary

    The tweet announces the availability of a proof‑of‑concept for the Libfuse CVE‑2026‑33150 and CVE‑2026‑33179, highlighting severe impact types but providing no evidence of active exploitation, patches, or false positives.

    01050192
    8.8K followersView on X
  • kinneko@kinneko
    Disclosure

    Critical libfuse io_uring Vulnerabilities Threaten Linux and Kubernetes Infrastructure https://securityonline.info/libfuse-io-uring-vulnerabilities-cve-2026-33150-cve-2026-33179/

    Post summary

    The text announces the discovery of two critical libfuse io_uring CVEs affecting Linux and Kubernetes infrastructure, but provides no additional technical or exploit details.

    00002119
    2.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33179 libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init… https://www.cve.org/CVERecord?id=CVE-2026-33179

    Post summary

    CVE‑2026‑33179 is a null pointer dereference and memory leak in libfuse versions 3.18.0 to 3.18.1.

    01010176
    56.8K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Libfuse: disponibile #PoC per lo sfruttamento delle CVE-2026-33150 e CVE-2026-33179 Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔸 Privilege Escalation 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/libfuse-disponibile-poc-per-lo-sfruttamento-delle-cve-2026-33150-e-cve-2026-33179 🔄 Aggiornamenti disponibi… https://t.co/STp5RX5LUP

    Post summary

    The tweet announces a publicly available proof‑of‑concept for CVE‑2026‑33150 and CVE‑2026‑33179 in Libfuse, detailing the associated risk types and linking to the PoC.

    0000056
    607 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibfuse_projectlibfuse---

Explore more